The file's text, extracted by GovTribe without its formatting.
Providing Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Security Operations Center (SOC) Highly Adaptive Cybersecurity Services (HACS) Draft BPA CLIN Structure/B Table
Base Year
| CLIN 0001 SECURITY OPERATIONS CENTER SUPPORT (LH) | Gov Site Rate | Contractor Site Rate | Unit | | | |
| | | | $ | $ | Hourly |
(See Price Attached Price List)
| 0001a Functional Area 1 Management and Control | | | | Not Separately Priced | |
| 0001b Functional Area 2 Information Security Incident Management | | Not Separately Priced | | | |
| 0001c Functional Area 3 Vulnerability Management | | | | Not Separately Priced | |
| 0001d Functional Area 4 Adversary and Advanced Operations | | | Not Separately Priced | | |
| 0001e Functional Area 5 SOC Architecture, Engineering, Deployment and Management | Not Separately Priced | | | | |
| 0001f Functional Area 6 SOC Capabilities Improvement Activities | | | | | Not Separately Priced |
CLIN 0002 MANAGED SECURITY SERVICES SUPPORT (MSS)
| 0002A Functional Area 2 Information Security Incident Mgmt |
| Small Org |
Up to 2000 Medium Org 2001-5000 Large Org Over 5000 Unit
Real-Time Alert Monitoring and Triage Up to 1TB median network traffic per month
| Up to 100GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 100GB-500GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
| Over 500GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
Real-Time Alert Monitoring and Triage 1TB – 25TB average network traffic per month
| Up to 100GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 100GB-500GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
| Over 500GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
Real-Time Alert Monitoring and Triage Over 25TB average network traffic per month
| Up to 100GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 100GB-500GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
| Over 500GB median log data per day |
| $ |
| $ |
| $ |
| Monthly rate per device |
Incident Report Acceptance and Coordination Up to 25 average SOC tickets per month Note: Not including reconnaissance scans
| Up to 2 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| 3-6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| Over 6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
Incident Report Acceptance and Coordination 26-100 average SOC tickets per month Note: Not including reconnaissance scans
| Up to 2 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| 3-6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| Over 6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
Incident Report Acceptance and Coordination Over 100 average SOC tickets per month Note: Not including reconnaissance scans
| Up to 2 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| 3-6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| Over 6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
Incident Analysis Up to 25 average SOC tickets per month Note: Not including reconnaissance scans
| Up to 2 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| 3-6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| Over 6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
Incident Analysis 26-100 average SOC tickets per month Note: Not including reconnaissance scans
| Up to 2 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| 3-6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| Over 6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
Incident Analysis Over 100 average SOC tickets per month Note: Not including reconnaissance scans
| Up to 2 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| 3-6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
| Over 6 average incidents per month |
| $ |
| $ |
| $ |
| Monthly |
Forensic Artifact Analysis and Malware Analysis 1 average analyses per month
Forensic Artifact Analysis and Malware Analysis 2-3 average analyses per month
Forensic Artifact Analysis and Malware Analysis Over 3 average analyses per month
Containment, Eradication, & Recovery Up to 2 average incidents per month Note: Not including reconnaissance scans
Containment, Eradication, & Recovery 3-6 average incidents per month Note: Not including reconnaissance scans
Containment, Eradication, & Recovery Over 6 average incidents per month Note: Not including reconnaissance scans
| Fly-Away Incident Response |
| $ |
| $ |
| $ |
| Per trip |
| 0002B Functional Area 3 Vulnerability Management |
| Small Org |
Up to 2000 Medium Org 2001-5000 Large Org Over 5000 Unit
| 0002Ba Asset Mapping |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 0002Bb Vulnerability Scanning |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 0002Bc Vulnerability Assessments |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 0002Bd Phishing Assessment |
| $ |
| $ |
| $ |
| Assessment rate per email account |
| 0002Be Wireless Assessment |
| $ |
| $ |
| $ |
| Assessment rate |
0002Bf Web Application Assessment Note: Characteristics that delineate between basic, standard, and complex include, but are not limited to, number of discrete URIs, open vs closed source, size of code base, and languages.
| Basic |
| $ |
| Assessment rate per web application |
| 0002Bg Operating System Security Assessment (OSSA) |
| $ |
| Assessment rate |
| 0002Bh Database Assessment |
| $ |
| Assessment rate per database instance |
| 0002C | Functional Area 4 Adversary & Advanced Operations |
| Small Org | |
Up to 2000 Medium Org 2001-5000 Large Org Over 5000 Unit
0002Ca Threat Hunting Note: Characteristics that delineate between basic, standard, and complex include, but are not limited to, number and complexity of TTPs, and number of devices.
0002Cb Adversary Emulation Note: Characteristics that delineate between basic, standard, and complex include, but are not limited to, number of APTs, number of devices, and complexity of rules of engagement.
| 0002D Functional Area 5 SOC Architecture, Engineering, Deployment & Mgmt. |
| Small Org |
Up to 2000 Medium Org 2001-5000 Large Org Over 5000 Unit
| 0002Da Security Architecture Review (SAR) |
| $ |
| $ |
| $ |
| Assessment rate |
| 0002Db Network Security Capability Deployment and Management |
| $ |
| $ |
| $ |
| Per device per capability (e.g., a device with two capabilities would count as two) |
| 0002Dc Endpoint Security Capability Deployment and Management |
| $ |
| $ |
| $ |
| Monthly rate per device |
| 0002Dd Cloud Security Capability Deployment and Management |
| $ |
| $ |
| $ |
| Monthly rate per user |
| 0002De SOC Tool and Enclave Deployment and Management |
| $ |
| $ |
| $ |
| Per capability per analyst |
0002Df Sensor and Analytics Tuning Note: Characteristics that delineate between basic, standard, and complex include, but are not limited to, number of signatures, number of analytics, and type of capability.
0002Dg Custom Analytics and Detection Creation Note: Characteristics that delineate between basic, standard, and complex include, but are not limited to, type of capability and complexity of requirements/analytic/signature.
| Basic |
| $ |
| Per signature/analytic |
| 00002E Functional Area 6 SOC Capabilities Improvement Activities |
| Small Org |
Up to 2000 Medium Org 2001-5000 Large Org Over 5000 Unit
| 0002Ea Cyber Range |
| $ |
| $ |
| $ |
| Per analyst per instance |
| CLIN 0003 Surge/Emerging Threat Support (Optional) | Gove Site Rate | Contractor Site Rate | Unit | | | |
| | | | $ | $ | Hourly |
CLIN 0004 Other Direct Cost NTE
· Travel
· MISC???
Examples:
1. Devices are defined as discrete, individual component entities within the technology stack of the enterprise
1. Devices include (but are not limited to): network connection endpoints, computing platform and data storage hosts, network components, and security (both cybersecurity – e.g., firewalls or bulk encryptors – and physical access control) components. One device may have multiple endpoints (e.g., router or switch). Endpoint connections may be physical (e.g., 10/100/1000 Base-T RJ-45 Cat6+ Ethernet, shielded or unshielded twisted pair, coaxial, single- or multimode fiber, LAN or Metro Ethernet) or wireless (e.g., Wi-Fi access point radio) or virtual connection entry points (e.g., VPN endpoint).
1. Devices are installed in both physical and virtual forms across on-premises and cloud environments, and in remote office (home office) or travel locations (hotels, vendor or taxpayer premises).
1. Device functions include servers, printers, client hosts (laptops, workstations), VoIP phones, mobile phones, FAX machines and special-purpose devices (e.g., multifunction devices, fingerprint or badge readers)
1. Devices in this context may include special purpose nodes (e.g., database management system instance, network-attached storage)